Aggregator
Researcher Exploits Regex Filter Flaw to Gain Remote Code Execution
Target application included a username field restricted by a frontend regex filter (/^[a-zA-Z0-9]{1,20}$/), designed to accept only alphanumeric characters. While this initially appeared robust, the researcher discovered that the backend failed to revalidate inputs after the regex check. This oversight allowed specially crafted payloads to bypass client-side controls and execute arbitrary commands on the server. […]
The post Researcher Exploits Regex Filter Flaw to Gain Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
New ‘Bring Your Own Installer (BYOI)’ technique allows to bypass EDR
Benchmarks Q&A: What the finance sector’s new X9 PKI standard signals for other industries
As organizations brace for the rising tide of machine identities and prepare for a post-quantum cryptographic era, a quiet but crucial shift is underway in the financial sector: the deployment of a new, private PKI standard designed specifically to meet … (more…)
The post Benchmarks Q&A: What the finance sector’s new X9 PKI standard signals for other industries first appeared on The Last Watchdog.
The post Benchmarks Q&A: What the finance sector’s new X9 PKI standard signals for other industries appeared first on Security Boulevard.
TikTok Hit with €530 Million Fine Over Data Transfers to China
Irish Data Protection Commission (DPC) has imposed a landmark €530 million fine on TikTok Technology Limited for illegally transferring European Economic Area (EEA) user data to China and failing to meet transparency obligations under the General Data Protection Regulation (GDPR). The decision, finalized on May 5, 2025, follows a multi-year inquiry into TikTok’s data governance […]
The post TikTok Hit with €530 Million Fine Over Data Transfers to China appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2022-32924 | Apple watchOS up to 9.0.2 Kernel memory corruption (HT213491)
CVE-2022-32924 | Apple tvOS up to 16.0 Kernel memory corruption (HT213492)
CVE-2022-32924 | Apple macOS Kernel memory corruption (HT213488)
CVE-2022-2711 | Import any XML or CSV File to Plugin up to 3.6.8 on WordPress ZIP Archive path traversal
CVE-2022-3872 | QEMU SDHCI Device sdhci_read_dataport/sdhci_write_dataport off-by-one (Nessus ID 232075)
CVE-2024-22393 | Apache Answer up to 1.2.1 File Upload Pixel Flood resource consumption
CVE-2024-31860 | Apache Zeppelin up to 0.10.x path traversal
CVE-2025-1121 | Google ChromeOS 123.0.6312.112 Installer privileges management (Issue 336153)
CVE-2025-1122 | Google ChromeOS 122.0.6261.132 TPM2 Reference Library NV_Read out-of-bounds write
CVE-2025-1568 | Google ChromeOS 131.0.6778.268 Project Configuration project.config code injection
CVE-2025-1566 | Google ChromeOS 129.0.6668.36 DNS Query missing encryption
CVE-2025-3248 | langflow-ai langflow up to 1.2.0 HTTP Request /api/v1/validate/code missing authentication (EDB-52262)
Полмиллиарда на алтарь свободы слова — Трамп посадил CISA на бюджетную диету
xAI API Key Leak Exposes Proprietary Language Models on GitHub
Employee at Elon Musk’s artificial intelligence firm xAI inadvertently exposed a private API key on GitHub for over two months, granting unauthorized access to proprietary large language models (LLMs) fine-tuned on internal data from SpaceX, Tesla, and Twitter/X. Security researchers at GitGuardian discovered the leak, which compromised 60 private and unreleased models, including development versions […]
The post xAI API Key Leak Exposes Proprietary Language Models on GitHub appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.